CVE-2026-1078
Received
Received - Intake
Arbitrary File Write in Pega Browser Extension via Malicious Sites
Publication date: 2026-04-07
Last updated on: 2026-04-07
Assigner: Pegasystems Inc.
Description
Description
An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robotic Automation version 22.1 or R25 users who are running automations that work with Google Chrome or Microsoft Edge. A bad actor could create a website that includes malicious code. The vulnerability could occur if a Robot Runtime user navigates to the malicious website.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| pega | robotic_automation | 22.1 |
| pega | robotic_automation | r25 |
| pega | browser_extension | 3.1.45 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-284 | The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |